Your data does not have to leave your control for you to use AI.

We bring the model to your data, not your data to the model. It is deployed inside your own environment: your cloud, your region, your governance boundary. For most enterprises this is the first question they ask, and it has a good answer.

Certified across the Claude stack
Claude Certified Architect — FoundationsClaude Certified DeveloperClaude Certified Architect — ProfessionalClaude Certified AssociateClaude Code Partner

Where your data lives is a deployment decision, not a fixed default.

The model runs in every major cloud. It can be deployed inside your own AWS account through Amazon Bedrock, your Google Cloud project through Vertex AI, or your Microsoft Azure tenant, each keeping inference in the region and account you already govern. Where a first-party deployment fits better, inference can be pinned to a named region instead.

We pick the option that matches your data-residency rules. We do not ask you to change them to fit a tool.

Residency, in your control

  • Deployed inside your own cloud account, no new vendor infrastructure.
  • Data stored in the region you choose.
  • Requests processed in that same region.
  • You remain the data controller; the model runs as your processor.

What the model does with your data.

By default, your inputs and outputs are never used to train the model. API data is deleted from Anthropic’s systems within thirty days, and zero-retention is available for workloads where even that is too long.

Every line here is Anthropic’s written policy, verifiable on its own privacy pages at privacy.claude.com, something your compliance team can read for themselves. And when the model runs inside your own cloud, retention is governed by your policies, not ours.

Who can reach it.

Your identity, your controls

Because the deployment sits inside your environment, access runs on your identity and your controls: the same single sign-on, role-based access, and audit logging your other systems already use.

Read-only where the work allows

We work under read-only access where the work allows, scoped to the project and agreed in writing,

Approval before production

and nothing reaches production without your approval.

You own everything

Your content, the model's outputs, and anything we build with you stay yours.

Sector rules are the real constraint, not residency in the abstract.

In the most regulated industries, financial services, healthcare, government, the rules set where data can go and under what conditions. The law generally governs how data moves, not whether AI is allowed to touch it. We design the deployment around those rules from the start, so the question your regulator will ask already has an answer by the time they ask it.

Financial services

In your own region and cloud, under SOC 2 Type II. Market and client data never leaves your regulatory boundary.

Healthcare

HIPAA-ready deployment with a BAA available. Protected health data stays inside your environment.

Government & public sector

Deployed in-country, in your own government cloud. Data residency and sovereignty by design.

How this works in a regulated environment.

Security is part of the design, not a review bolted on at the end. We start by mapping where your sensitive data lives and what is allowed to touch it, deploy the model so that boundary is never crossed, and hand you the architecture in writing: what connects to what, who can access it, and where the logs go.

Larger and sector-regulated rollouts run on our enterprise track.

Questions your team will ask.

Usually the opposite. It is how we prefer to work. The model is deployed inside your own cloud account, so your data stays where it already is and the model reaches it under your existing controls.

Not by default. Anthropic does not train on your API inputs or outputs unless you explicitly opt in. The full commitment is on Anthropic's privacy pages, written so you can forward it to your compliance team.

Anthropic deletes API inputs and outputs within thirty days by default, and zero-retention arrangements are available where that matters. When the deployment sits in your own cloud, retention follows your policies.

All the major ones: AWS, Google Cloud, and Azure, as well as first-party regional deployment. We fit your environment rather than asking you to fit ours.

Both depend on scope. The Deployment Diagnostic puts a number and a payback period on it, and the Deployment Path shows the shape of the timeline from there.

Thirty minutes. No pitch.

Bring your compliance or security lead. We will walk through where your data would live, who could reach it, and what your regulator will want to see, and you will leave knowing whether this works inside your rules.